MAL-2026-12457
Malicious code in streak-bucket-core (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (4145bc51e507e0a8b64d1267c16b0c9c8e80950a08bcf0a320b03fb8a1875b26) streak-bucket-core@1.0.0 advertises itself as a small dependency-free calendar/day-math helper library, but its declared main entry index.mjs is ~521 KB and contains, after a short block of legitimate-looking Intl-based helpers, an embedded Windows PE payload and dropper logic at module top level. A `_decode` helper hex-decodes strings; a `_cfg` object holds hex-encoded fields that decode to the per-user Windows Startup folder path (`AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup`), the filename `vite-native-helper.exe`, and `NTUSER.DAT`; a `_bin` array of hex chunks concatenates and decodes to a byte sequence beginning with the MZ header and the `This program cannot be run in DOS mode.` stub, i.e. a Windows PE executable. Because this code sits at the top level of the module referenced by the package's main export, simply importing/requiring the package on a Windows host writes the reconstructed executable into the current user's Startup folder under the cover-story name `vite-native-helper.exe`, which Windows then auto-runs at every subsequent user logon. Adjacent comments (`startup self-check`, `browser-safe`, `touches no network and no filesystem`) and the Vite-adjacent filename appear to be cover text. The hex encoding of the destination path, filename, and payload contents indicates deliberate concealment rather than incidental data.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for streak-bucket-core (npm). Pin to a known-safe version or switch to an alternative.